Description
Missing authorization checks in the Backend Routing of TYPO3 CMS versions 9.0.0β9.5.54, 10.0.0β10.4.53, 11.0.0β11.5.47, 12.0.0β12.4.36, and 13.0.0β13.4.17 allow backend users to directly invoke AJAX backend routes without having access to the corresponding backend modules.
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2011-0832 Vulnerability (CVE-2011-0832)
Drupal Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-6212)
Oracle Database Server CVE-2015-0457 Vulnerability (CVE-2015-0457)
WordPress Plugin GDPR Cookie Consent Security Bypass (1.8.2)
ReviveAdserver Improper Authentication Vulnerability (CVE-2016-9124)